Nubank logo

Nubank

IT Risk Senior Specialist

Hybrid

Part remote, part office, you need to live within commuting distance of a named location.

Hybrid · Ciudad de México

Employer listed it 8 weeks ago · Added yesterday

Been open since 8 weeks ago. Long-running listings are sometimes left up after the role is filled.

Salary

Not stated

Location

Hybrid · Ciudad de México

Timezone

Not stated

Contract

Full-time

Experience

Senior

Category

Other

This employer didn't state pay. Jobs like this usually pay around $125k–$205k a year, a typical range taken from 166 senior-level other roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Hybrid

This role is only partly remote, the employer expects time in the office around Ciudad de México, Hybrid, so you need to live within commuting distance.

What the employer says

  • Source listing states candidate location: "Ciudad de México, Hybrid"
  • Listing mentions "Hybrid"

What Nomaders makes of it

  • Not suitable if you plan to move between countries

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About Nu

Nu serves more than 140 million customers, guided by a mission to fight complexity and empower people. The company has been leading an industry transformation through innovative products and human-centered services.

Proprietary technology and data at scale power Nu’s digital platform, built to promote financial access, advancement, and transparency. Its business model thrives on customer love and lower costs, feeding a flywheel of growth and profitability. Visit our Institutional Page

About the Role

Strategic and regulatory, centered on the design and strengthening of the Technology Risk framework, and on overseeing its implementation through the Technology Risk area and the business areas, ensuring comprehensive, forward-looking management aligned with regulation and the company’s strategy. Supports the oversight and development of the Technology Risk function, defining frameworks, metrics, and guidelines, and supervising the proper management of risks arising from systems, data, infrastructure, and technology third parties. Acts as the main point of contact with governing bodies and regulators on IT Risk matters, coordinates the response to major incidents and technology crises, and helps execute tests, assessments, and monitoring of the technology environment.

Responsibilities

Define, update, and oversee the Technology Risk framework, including policies, standards, methodologies, and assessment and reporting criteria.

Establish, update, and monitor technology risk metrics (KRIs, RAS), consolidating the view of exposure and trends for governing bodies.

Prepare responses and coordinate attention to regulatory and audit requests related to Technology Risk, interacting directly with those authorities when appropriate.

Oversee the management of high-materiality technology and cybersecurity incidents, including proper classification, root-cause analysis, and definition of corrective actions.

Provide guidance and challenge technology risk assessments for new products, features, and architectures, ensuring consistency and completeness.

Design and maintain IT Third-Party Risk frameworks, aligned with institutional standards and regulatory requirements.

Oversee the quality and consistency of IT and cybersecurity control testing, technology RCSAs, and incident monitoring.

Act as a key advisor to the leadership of Risk, Engineering, Security, Data, and other areas, fostering a strong culture of Technology Risk management.

Qualifications

Minimum of 5-6 years of experience in cybersecurity or IT Risk Management.

Bachelors’ degree in Engineering, Computer Science, Information Technology, a Risk Management related field, or equivalent experience.

In-depth knowledge of IT and cybersecurity risk management concepts, practices and methods.

Understanding of cloud computing models such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Familiarity with cloud providers like Amazon Web Services (AWS) and serverless technologies.

Understanding of cybersecurity concepts such as confidentiality, integrity and availability, supply chain risks, cryptography, endpoint and network security, cloud security, mobile security, API security, Cyberincident management, etc.

Understanding of DevOps practices and tools used in cloud environments, such as continuous integration/continuous deployment (CI/CD) pipelines and containerization.

Understanding of Business Continuity and Disaster Recovery (BC/DR) practices, along with experience executing and coordinating the full Business Continuity Management lifecycle and contingency response.

Fluent in English and Spanish, with exceptional communication skills to articulate complex risk scenarios and strategies effectively.

Demonstrated ability and experience to thrive in a tech-driven environment, ensuring the safe and practical use of technology through targeted challenge and inquiry directed at process and system owners.

Requirements

  • ·Minimum of 5-6 years of experience in cybersecurity or IT Risk Management.
  • ·Bachelors’ degree in Engineering, Computer Science, Information Technology, a Risk Management related field, or equivalent experience.
  • ·In-depth knowledge of IT and cybersecurity risk management concepts, practices and methods.
  • ·Understanding of DevOps practices and tools used in cloud environments, such as continuous integration/continuous deployment (CI/CD) pipelines and containerization.
  • ·Understanding of Business Continuity and Disaster Recovery (BC/DR) practices, along with experience executing and coordinating the full Business Continuity Management lifecycle and contingency response.

Benefits

  • ·Chance of earning equity at Nu
  • ·Extended maternity and paternity leaves
  • ·Health and life insurance
  • ·Dental and Vision Insurance
  • ·NuCare - Our mental health and wellness assistance program

How to apply

  1. 1Check the flexibility label above, hybrid, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Nubank, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 1d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open other roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $125k–$205k · You'll be taken to the employer's careers page.